You paid for SSL. The address bar still complains. One stylesheet or script loaded over http:// is enough for browsers to label the page unsafe — especially on checkout and account pages.
Why this hurts the business
Visitors don’t debug mixed content. They leave. Ads that land on a warning page convert poorly. Some payment providers refuse to run on insecure contexts.
Typical sources
- Hard-coded
http://image URLs in old posts - Third-party widgets still on HTTP
- CDN or font URLs not updated after the HTTPS migration
- Canonical or og:image tags pointing at HTTP
How WebPulse helps
We inventory mixed content, rewrite or proxy assets, enforce HTTPS redirects, and set security headers so the padlock stays honest. That work lives under Security & reliability and often shows up in a free audit as a high-priority trust fix.
Related reading: What an SSL certificate actually protects.
Bottom line: HTTPS only helps if every asset is HTTPS. Half-migrated sites train customers to distrust you.